DrupalÖ÷Ìâ×é¼þ¶à¸ö·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-04-19

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬ £¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬£¬£¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-10909£¬£¬£¬ £¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬£¬£¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-10910£¬£¬£¬ £¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬£¬£¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-10911£¬£¬£¬ £¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬£¬£¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾

Drupal 8.5»ò¸üÔç°æ±¾£¬£¬£¬ £¬£¬£¬£¬ £¬Drupal 8.6£¬£¬£¬ £¬£¬£¬£¬ £¬Drupal 7

ÊÜÓ°ÏìµÄ×é¼þ

jQuery < 3.4.0

Symfony 2.7.0 to 2.7.50, 2.8.0 to 2.8.49, 3.4.0 to 3.4.25, 4.1.0 to 4.1.11 and 4.2.0 to 4.2.6


·ì϶¸ÅÊö


DrupalÊÇDrupalÉçÇøµÄÒ»Ì×ʹÓÃPHP˵»°¿ª·¢µÄ¿ªÔ´ÄÚÈÝÖÎÀíϵͳ¡£¡£¡£¡£¡£Drupal°ä²¼Á˰²È«¸üУ¬£¬£¬ £¬£¬£¬£¬ £¬ÒÔ½â¾öDrupal CoreÖеĶà¸ö°²È«·ì϶£¬£¬£¬ £¬£¬£¬£¬ £¬ÕâЩ·ì϶¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷Õß·ÛËéÊýÊ®Íò¸öÍøÕ¾µÄ°²È«ÐÔ¡£¡£¡£¡£¡£


ÆäÖÐÒ»¸ö°²È«·ì϶ÊÇÒ»¸ö¿çÕ¾µã¾ç±¾£¨XSS£©·ì϶£¬£¬£¬ £¬£¬£¬£¬ £¬Ëü´æÔÚÓÚµÚÈý·½²å¼þÖУ¬£¬£¬ £¬£¬£¬£¬ £¬³ÆÎªJQuery£¬£¬£¬ £¬£¬£¬£¬ £¬ÕâÊÇÊý°ÙÍòÍøÕ¾Ê¹ÓõÄ×îÊ¢ÐеÄJavaScript¿â£¬£¬£¬ £¬£¬£¬£¬ £¬Ò²Ô¤Ïȼ¯³ÉÔÚDrupal CoreÖÓ×£¡£¡£¡£¡£¸Ã·ì϶ÉÐδ·ÖÅäCVE±àºÅ¡£¡£¡£¡£¡£


ÆäÓàÈý¸ö°²È«·ì϶´æÔÚÓÚDrupal CoreʹÓõÄSymfony PHP×é¼þÖУº

CVE-2019-10909

ʹÓÃPHPÄ£°åÒýÇæµÄ±íµ¥Ö÷Ìâʱ£¬£¬£¬ £¬£¬£¬£¬ £¬ÑéÖ¤ÐÂÎÅδ±»×ªÒ壬£¬£¬ £¬£¬£¬£¬ £¬µ±ÑéÖ¤ÐÂÎÅ¿ÉÄÜÔ̺¬Óû§ÊäÈëʱ£¬£¬£¬ £¬£¬£¬£¬ £¬¿ÉÄܻᵼÖÂXSS¡£¡£¡£¡£¡£


CVE-2019-10910

´Óδ¹ýÂ˵ÄÓû§ÊäÈëÅÉÉúµÄ·þÎñID¿ÉÄܵ¼ÖÂÖ´ÐÐÈκÎËÁÒâ´úÂ룬£¬£¬ £¬£¬£¬£¬ £¬´Ó¶øµ¼Ö¿ÉÄܵÄÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£


CVE-2019-10911

¹¥»÷ÕßÄܹ»Åú¸Ä¼ÇסÎÒµÄcookie²¢×÷Ϊ·ÖÆçµÄÓû§½øÐÐÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£


½¨¸´½¨Òé


ĿǰÒÑÓÐа汾ÈçÏ£¬£¬£¬ £¬£¬£¬£¬ £¬ÇëÓû§ÊµÊ±¸üС£¡£¡£¡£¡£

Drupal 8.6.15

https://www.drupal.org/project/drupal/releases/8.6.15

Drupal 8.5.15

https://www.drupal.org/project/drupal/releases/8.5.15

Drupal 7.66

https://www.drupal.org/project/drupal/releases/7.66

Symfony 2.7.51, 2.8.50, 3.4.26, 4.1.12 and 4.2.7

https://github.com/symfony/symfony/commit/ab4d05358c3d0dd1a36fc8c306829f68e3dd84e2

jQuery 3.4.0

https://blog.jquery.com/2019/04/10/jquery-3-4-0-released/


²Î¿¼Á´½Ó


https://www.drupal.org/security